Input validation error in envoy - CVE-2023-27488
Published: April 5, 2023 / Updated: April 6, 2023
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to insufficient validation of user-supplied input when "failure_mode_allow: true" is configured for ext_authz filter. A remote attacker can pass specially crafted input to the application and gain elevated privileges on the target system.
Affected software
Amazon Linux AMI
Istio
OpenShift Service Mesh
IBM Watson Assistant for IBM Cloud Pak for Data
How to mitigate CVE-2023-27488
Istio - addressed in versions 1.15.7, 1.16.4, 1.17.2
OpenShift Service Mesh - update to 2.2.9
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
External References
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-9g5w-hqr3-w2ph
- https://github.com/envoyproxy/envoy/releases/tag/v1.25.4
- https://github.com/envoyproxy/envoy/releases/tag/v1.24.5
- https://github.com/envoyproxy/envoy/releases/tag/v1.23.7
- https://github.com/envoyproxy/envoy/releases/tag/v1.22.10